A newly disclosed vulnerability in the popular Forminator Forms WordPress plugin could allow unauthenticated attackers to upload arbitrary files, including executable PHP files, potentially leading to remote code execution and complete website compromise.
Forminator Forms has more than 600,000 active installations, making the vulnerability a significant security concern for WordPress website owners. However, the issue does not automatically affect every site using the plugin. According to Wordfence, exploitation requires a form containing both a File Upload field and a Select field.
Unauthenticated attackers could upload malicious files
The vulnerability is particularly serious because an attacker does not need to be logged in to attempt exploitation.
According to Wordfence’s security disclosure, vulnerable configurations can allow attackers to upload arbitrary files through a Forminator form. This includes executable PHP files, which could potentially enable malicious code to run on the affected server.
Successful exploitation could ultimately result in a complete compromise of a WordPress website.
The specific configuration required for exploitation is important. Wordfence reported that the vulnerability can be exploited on sites where a Forminator form contains both a File Upload field and a Select field.
More than 600,000 active installations
The scale of Forminator’s deployment makes the issue particularly significant for the WordPress ecosystem.
The plugin has more than 600,000 active installations, although this figure should not be interpreted as meaning that all of those websites are vulnerable. The risk depends on the plugin version and the configuration of forms on each individual site.
For businesses, publishers, organisations and other website operators, a compromised WordPress installation can have consequences extending beyond the website itself. Attackers who gain the ability to execute code may be able to modify website content, create malicious accounts, deploy malware or attempt to access other information stored on the server.
Forminator developers released a security update
Wordfence said it provided full vulnerability details to the Forminator team through its Vulnerability Management Portal on July 14, 2026.
The developer acknowledged the report on July 20 and released a patched version on July 31.
At the time of Wordfence’s disclosure, Forminator Forms version 1.56.2 was identified as the patched version.
Website administrators using Forminator should check their installed version and update to the latest available release.
What WordPress administrators should do
Website owners using Forminator Forms should take several security precautions:
- Update Forminator Forms to version 1.56.2 or the latest available patched release.
- Review forms that use both File Upload and Select fields.
- Check WordPress security logs for unusual file-upload activity or unexpected changes.
- Review recently created administrator accounts and other suspicious changes.
- Ensure WordPress core, themes and other plugins are fully updated.
- Maintain regular, tested backups.
- Consider using a reputable web application firewall and security monitoring solution.
Wordfence said its firewall’s built-in Malicious File Upload protection protects sites against exploits targeting this vulnerability, including sites using its free version.
A reminder about WordPress plugin security
The Forminator vulnerability highlights the security risks associated with third-party WordPress plugins, particularly those that handle user-submitted files.
File-upload functionality requires careful validation because attackers can attempt to disguise executable code as legitimate uploads. For businesses relying on WordPress for websites, publishing platforms, e-commerce operations or customer-facing services, keeping plugins updated should be treated as a routine security priority.
The disclosure also demonstrates the importance of responsible vulnerability reporting. Wordfence credited security researcher daroo with discovering and reporting the vulnerability through its Bug Bounty Program.
With Forminator installed on more than 600,000 WordPress sites, administrators using the plugin should review their configuration and ensure they are running a patched version.
Source: Wordfence
